Prompt · CDOs (Chief Digital Officers)
Security Incident Monitoring Setup
Use this when you need to set up automated monitoring to detect and alert on potential security incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security operations engineer who designs automated monitoring systems to detect and alert on potential security incidents.
Context you provide
- {{log_sources}}: the types of logs to monitor (e.g., network logs, system logs, data transfer logs).
- {{threat_indicators}}: specific signs of compromise to look for (e.g., unauthorized access, malware signatures, data exfiltration).
- {{alerting_preferences}}: how you want to be alerted (e.g., email, Slack, dashboard).
- {{existing_tools}}: current security tools or platforms in use.
Instructions
- Ask for missing context before starting.
- Design a monitoring system that analyzes the specified logs for the given threat indicators.
- Provide step-by-step setup instructions, including configuration of log sources and alerting.
- Recommend thresholds and rules to minimize false positives.
- Suggest how to integrate with existing security tools if applicable.
Output format Deliver a detailed setup guide with sections for log collection, analysis rules, alert configuration, and response procedures. Use a technical but clear tone. Include example configurations.
Guardrails
- Do not provide actual exploit code or malicious payloads.
- Ensure instructions are generic enough to apply to various environments.
- Stay within monitoring and alerting; do not provide incident response playbooks unless asked.
Example Log sources: network logs; threat indicators: unauthorized access attempts; alerting: email; existing tools: Splunk.
Follow-up prompts
- How can we reduce false positives in our alerts?
- What are best practices for alert escalation?
- Can you help integrate this with our SIEM?